EDBT 2026 Demo / reviewers in the wild / expert
Rui Ning
dblp:211/2892
· DBLP profile ↗
33ranked-venue papers
8as first author
28since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 12 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 5 · 1 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Deep Incomplete Multi-View Clustering via Hierarchical Imputation and AlignmentabstractIncomplete multi-view clustering (IMVC) aims to discover shared cluster structures from multi-view data with partial observations. The core challenges lie in accurately imputing missing views without introducing bias, while maintaining semantic consistency across views and compactness within clusters. To address these challenges, we propose DIMVC-HIA, a novel deep IMVC framework that integrates hierarchical imputation and alignment with four key components: (1) view-specific autoencoders for latent feature extraction, coupled with a view-shared clustering predictor to produce soft cluster assignments; (2) a hierarchical imputation module that first estimates missing cluster assignments based on cross-view contrastive similarity, and then reconstructs missing features using intra-view, intra-cluster statistics; (3) an energy-based semantic alignment module, which promotes intra-cluster compactness by minimizing energy variance around low-energy cluster anchors; and (4) a contrastive assignment alignment module, which enhances cross-view consistency and encourages confident, well-separated cluster predictions. Experiments on benchmarks demonstrate that our framework achieves superior performance under varying levels of missingness. Yiming Du, Rui Ning, Lusi Li |
AAAI | 4 |
| 2026 | Heterogeneous Graph Backdoor AttackabstractHeterogeneous Graph Neural Networks (HGNNs) excel in modeling complex, multi-typed relationships across diverse domains, yet their vulnerability to backdoor attacks remains unexplored. To address this gap, we conduct the first investigation into the susceptibility of HGNNs to existing graph backdoor attacks, revealing three critical issues: (1) high attack budget required for effective backdoor injection, (2) inefficient and unreliable backdoor activation, and (3) inaccurate attack effectiveness evaluation. To tackle these issues, we propose the Heterogeneous Graph Backdoor Attack (HGBA), the first backdoor attack specifically designed for HGNNs, introducing a novel relation-based trigger mechanism that establishes specific connections between a strategically selected trigger node and poisoned nodes via the backdoor metapath. HGBA achieves efficient and stealthy backdoor injection with minimal structural modifications and supports easy backdoor activation through two flexible strategies: Self-Node Attack and Indiscriminate Attack. Additionally, we improve the ASR measurement protocol, enabling a more accurate assessment of attack effectiveness. Extensive experiments demonstrate that HGBA far surpasses multiple state-of-the-art graph backdoor attacks in black-box settings, efficiently attacking HGNNs with low attack budgets. Ablation studies show that the strength of HBGA benefits from our trigger node selection method and backdoor metapath selection strategy. In addition, HGBA shows superior robustness against node feature perturbations and multiple types of existing graph backdoor defense mechanisms. Finally, extension experiments demonstrate that the relation-based trigger mechanism can effectively extend to tasks in homogeneous graph scenarios, thereby posing severe threats to broader security-critical domains. Lusi Li, Daniel Takabi, Masha Sosonkina, Rui Ning |
ICDCS | 5 |
| 2026 | TrojanEdge: Mutual Information-Enhanced Robust and Persistent Backdoor Attacks for Edge and On-Device Deployments
Zemin Chen, Austin Mao, Lusi Li, Rui Ning, Chunsheng Xin, Hongyi Wu |
INFOCOM | 6 |
| 2026 | ACS-Boot: Efficient Randomized Smoothing for Robustness Certification on Resource-Constrained Edge Devices
Lusi Li, Chunsheng Xin, Hongyi Wu, Rui Ning |
INFOCOM | 8 |
| 2026 | JITServe: SLO-aware LLM Serving with Imprecise Request Information
Wei Zhang 0044, Zhiyu Wu, Yi Mu 0005, Rui Ning, Banruo Liu, Nikhil Sarda, Myungjin Lee, Fan Lai 0001 |
NSDI | 4 |
| 2026 | OSCAR: O(1)-Step Convergence and Readily-deployable Congestion Control
Zhaochen Zhang, Feiyang Xue, Rui Ning, Keqiang He, Gianni Antichi, Zhimeng Yin 0001, Rui Li 0020, Zhengqi Cui, Zhehao Lin, Peirui Cao, Guihai Chen, Chen Tian 0001 |
NSDI | 3 |
| 2026 | D-SYNC: Enhancing Vehicle Localization with Dashcam-Satellite Image SynchronizationabstractThis paper introduces D-SYNC, a cutting-edge framework for enhancing the security and reliability of vehicle localization systems. D-SYNC offers an innovative solution to utilize dashcam footage for vehicle localization in the scenario of the primary localization system, GPS, under security attacks or simply failing to work. D-SYNC synchronizes the visual data from dashcam recordings with geotagged satellite imagery, achieving reliable vehicle positioning and trajectory mapping without precise dashcam-to-satellite alignment. D-SYNC introduces novel designs to address critical challenges, such as the limited field of vision in dashcam videos during real-world driving and how to correlate the significantly distinct spatial and temporal patterns between dashcam sequences and satellite images. Moreover, a novel geo-assisted loss function is introduced in D-SYNC that further elevates the performance of the localization process. D-SYNC surpasses existing methods and significantly increases vehicle localization accuracy. It achieves a 91% top-1 retrieval accuracy in urban environments and a 34% improvement in sub-10 meter localization error compared to benchmarks, relying solely on dashcam and satellite imagery. Peng Jiang 0027, Liuwan Zhu, Rui Ning, Hongyi Wu, Chunsheng Xin |
PerCom | 3 |
| 2026 | Efficient Backdoor Mitigation in Federated Learning With Contrastive Loss
Hal Ferguson, Rui Ning, Hongyi Wu, Liuwan Zhu, Chunsheng Xin, Mohammad Shahabuddin, Jiang Li 0001 |
IEEE Internet Things J. | 2 |
| 2026 | GhostBackdoor: A Resistant Backdoor AttackabstractThe robustness, security, and safety of artificial intelligence (AI) systems have become growing concerns, particularly as deep learning models are increasingly deployed in critical applications. Among emerging threats, backdoor attacks pose a serious risk by embedding hidden malicious behaviors into otherwise well-performing models. Although recent advances in detection techniques have improved defenses for computer vision systems, our findings demonstrate that even simple but carefully designed poisoning strategies can successfully evade these defenses. In this paper, we introduce GhostBackdoor, a novel backdoored model trained using a custom loss function and targeted data augmentation. The proposed loss function aligns neuron activations between clean and poisoned inputs, effectively masking activation anomalies, while the augmentation enforces strict location- and pattern-specific triggers that activate the backdoor only under specific conditions. After training, the model maintains behavior indistinguishable from a clean model unless exposed to the designated trigger with the specific pattern and at the designed locations. We evaluate GhostBackdoor against a broad range of leading defense mechanisms, most of which fail to detect the implanted backdoor. Our results highlight how the vast hypothesis space of deep learning models can be exploited to conceal malicious activations, underscoring the need for more robust security strategies in AI-driven systems, including those used in Internet of Things (IoT) applications. Omid Rajabi Rostami, Rui Ning, Chunsheng Xin, Jin-Hee Cho, Jiang Li 0001, Hongyi Wu |
IEEE Internet Things J. | 2 |
| 2026 | TD3 Integrated Fuzzy-Finite Variable Admittance Control of Posture Estimation and Adjustment for Robotic Precise Peg-in-HoleabstractIn unstructured environment, the robot faces the Precise Peg-in-Hole (PPiH) assembly as a non-cooperative issue. The posture uncertainty of the peg presents challenges in searching and inserting the hole. The purpose of the research is to eliminate the posture deviation between the peg and the hole with the force feedback. In this paper, the posture adjustment is divided into rough and fine processes. Firstly, for the rough adjustment, the force-angle samples from the end-effector are trained using a Multi-Layer Perceptron (MLP) model under peg-hole non-contact. The robot is guided by the MLP and adjusts the peg to roughly compensate for the posture deviation. Then, the robot brings the peg toward and contacts the hole. Secondly, for the fine adjustment, a Fuzzy-Finite Variable Admittance Control (FFVAC) model is established to estimate and adjust posture for different peg-hole contact states accurately. By integrating force information with fuzzy logic, the fuzzy inference system with fuzzy rules is developed based on the peg-hole contact states. According to the contact states, the twin delayed deep deterministic policy gradient (TD3) model finds the optimal admittance control parameters to achieve the surface close fitting of the peg and hole. Finally, comprehensive experiments are conducted under the unknown initial posture of the peg. The results are analysed by comparing with the stated of the arts of the posture adjustment methods regarding adjustment accuracy and operation time. The proposed method quickly reduces the posture deviation angle less than 0.2°, facilitates the following hole search and insertion works. Yi Liu 0045, Rui Ning, Hong Sang, Shuanghe Yu, Yan Yan 0023, Yunsheng Fan |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2026 | PGFormer: A Prototype-Graph Transformer for Incomplete Multiview ClusteringabstractIncomplete multiview clustering (IMVC) faces significant challenges due to missing data and inherent view discrepancies. While deep neural networks offer powerful representation learning capabilities for IMVC, existing methods often overlook view diversity and force representations across views to be identical, leading to 1) biased representations with distorted topologies and 2) inaccurate imputation for missing data, ultimately degrading clustering performance. To address these issues, we propose prototype-graph transformer (PGFormer), a novel IMVC framework that integrates prototype assignments, rather than direct representations, to enhance clustering performance. PGFormer leverages view-specific encoders to extract features from available samples in each view, employs a PGFormer designed to refine node embeddings, and reconstructs available samples using these refined embeddings. For each view, PGFormer utilizes a graph convolutional network (GCN) to model node-to-node topologies and generate semantic prototypes from the node embeddings. These view-specific prototypes and embeddings are then refined through dual attention mechanisms: prototype-to-prototype (P2P) self-attention and prototype-to-node (P2N) cross-attention, enabling a thorough exploration of multilevel topological relationships within each view. To address missing data, the cross-prototype imputation (CPI) module leverages the weighted prototype assignments from different views to impute missing samples using refined intraview prototypes. Building on this, the cross-view alignment module calibrates prototype assignments to ensure consistent predictions across views. Extensive experiments demonstrate that PGFormer can achieve superior performance compared with the baselines. Yiming Du, Rui Ning, Lusi Li |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2026 | Revisiting Flow Control in Node-Centric Datacenter NetworksabstractNode-centric Data Centers (NDCs) are highly flexible, cost-efficient, and failure-resilient, and have gained growing popularity in recent years. However, RDMA technology used in NDC still faces challenges, including high retransmission overhead, Head-of-Line Blocking (HoLB) and deadlock problems. Existing solutions for traditional data centers cannot simultaneously address these issues due to the unique topology and server transmission characteristics of NDC. In this paper, we propose a per-port flow control named PortFC for NDC. PortFC addresses the above problems through the designs of a Pause/Resume control signal, a per-port queue allocation method, an egress-detecting per-port flow control mechanism, and a server-aware queue scheduling method. Our evaluation shows that PortFC is free from retransmission, capable of eliminating HoLB and avoiding deadlocks. PortFC achieves 1.7-8.0 times higher throughput and reduces latency by 11.7%-87.7% compared to the state-of-the-art lossy RDMA based on IRN and the lossless RDMA method based on PFC. In particular, PortFC still demonstrates good performance in a Rail-only NDC with heterogeneous bandwidth domains. Peirui Cao, Rui Ning, Guangyu Zhao, Zhaochen Zhang, Chang Liu 0001, Yunzhuo Liu, Rui Li 0020, Chengyuan Huang, Tao Sun 0010, Guihai Chen, Baochun Li, Chen Tian 0001 |
IEEE Trans. Netw. | 2 |
| 2025 | Enabling Virtual Priority in Data Center Congestion ControlabstractIn data center networks, various types of traffic with strict performance requirements operate simultaneously, necessitating effective isolation and scheduling through priority queues. However, most switches support only around ten priority queues. Virtual priority can address this limitation by emulating multi-priority queues on a single physical queue, but existing solutions often require complex switch-level scheduling and hardware changes. Our key insight is that virtual priority can be achieved by carefully managing bandwidth contention in a physical queue, which is traditionally handled by congestion control (CC) algorithms. Hence, the virtual priority mechanism needs to be tightly coupled with CC. In this paper, we propose PrioPlus, a CC enhancement algorithm that can be integrated with existing congestion control schemes to enable virtual priority transmission. PrioPlus assigns specific delay ranges to different priority levels, ensuring that flows transmit only when the delay is within the assigned range, effectively meeting virtual priority requirements. Compared to Swift CC with physical priority queues, PrioPlus provides strict priority for high-priority flows without impacting performance sensibly. Meanwhile, it benefits low-priority flows from 25% to 41% as its priority-aware design enhances CC's ability to fully utilize available bandwidth once higher-priority traffic completes. As a result, in coflow and model training scenarios, PrioPlus improves job completion times by 21% and 33%, respectively, compared to Swift with physical priority queues. Zhaochen Zhang, Feiyang Xue, Keqiang He, Zhimeng Yin 0001, Gianni Antichi, Yizhi Wang 0004, Rui Ning, Haixin Nan, Xu Zhang 0006, Peirui Cao, Xiaoliang Wang 0001, Wan-Chun Dou, Guihai Chen, Chen Tian 0001 |
EuroSys | 8 |
| 2025 | PortFC: Designing High-performance Deadlock-free BCube NetworksabstractBCube is a modular data center network.Compared with other topologies, BCube has natural advantages, such as lower deployment costs and stronger failure recovery capabilities.However, RDMA technology used in BCube still faces challenges, including high retransmission overhead, Head-of-Line Blocking (HoLB) and deadlock problems.Existing solutions for traditional data centers cannot simultaneously address these issues due to the unique topology and server transmission characteristics of BCube.In this paper, we propose a per-port flow control named PortFC for BCube.PortFC addresses the above problems through the designs of a Pause/Resume control signal, a per-port queue allocation method, an egress-detecting per-port flow control mechanism, and a serveraware queue scheduling method.Our evaluation shows that PortFC is free from retransmission, capable of eliminating HoLB and avoiding deadlocks.PortFC achieves 1.7-8.0times higher throughput and reduces latency by 11.7%-87.7%compared to the state-of-the-art Peirui Cao, Rui Ning, Zhaochen Zhang, Chang Liu 0001, Rui Li 0020, Yongqi Yang, Yunzhuo Liu, Chengyuan Huang, Tao Sun 0010, Xiaodong Duan, Guihai Chen, Chen Tian 0001 |
ICS | 2 |
| 2025 | Energy-based Deep Incomplete Multi-View ClusteringabstractIncomplete multi-view clustering (IMVC) deals with real-world scenarios where certain views are partially missing, posing significant challenges to effective clustering. Most existing IMVC approaches face a trade-off: imputation-free methods suffer from information bias and imbalance, while full-imputation methods risk introducing and propagating noise. To overcome these limitations, we propose Energy-Based Deep Incomplete Multi-View Clustering (Energy-DIMC), a novel selective-imputation framework that leverages energy-based models (EBMs) to guide reliable imputations and robust clustering. EBMs assess data compatibility by assigning lower energy to more coherent structures, effectively modeling complex inter-view and inter-sample dependencies. Inspired by EBMs, Energy-DIMC integrates four key components: 1) a view feature projector that learns view-specific features and projects them into a common feature space; 2) an energy-guided selective imputation module that identifies the most reliable source view for each view based on view energies, and performs feature imputation only when cross-view transfer is feasible, avoiding unreliable imputations; 3) an energy-based representation fusion module that aggregates observed and selectively imputed features across views via a view attention mechanism, generating view-coherent representations; 4) an energy-enhanced contrastive alignment module that enforces consistency between view-specific and view-coherent representations using dual-level energy signals to preserve true positives. Extensive experiments demonstrate that Energy-DIMC outperforms state-of-the-art IMVC methods across diverse missing-view scenarios. The code is available at https://github.com/sunway677/EnergyIMVC. Yiming Du, Rui Ning, Lusi Li |
ACM Multimedia | 3 |
| 2025 | DictPFL: Efficient and Private Federated Learning on Encrypted GradientsabstractFederated Learning (FL) enables collaborative model training across institutions without sharing raw data. However, gradient sharing still risks privacy leakage, such as gradient inversion attacks. Homomorphic Encryption (HE) can secure aggregation but often incurs prohibitive computational and communication overhead. Existing HE-based FL methods sit at two extremes: encrypting all gradients for full privacy at high cost, or partially encrypting gradients to save resources while exposing vulnerabilities. We present **DictPFL**, a practical framework that achieves full gradient protection with minimal overhead. DictPFL encrypts every transmitted gradient while keeping non-transmitted parameters local, preserving privacy without heavy computation. It introduces two key modules: **Decompose-for-Partial-Encrypt (DePE)**, which decomposes model weights into a static dictionary and an updatable lookup table—only the latter is encrypted and aggregated, while the static dictionary remains local and requires neither sharing nor encryption; and **Prune-for-Minimum-Encrypt (PrME)**, which applies encryption-aware pruning to minimize encrypted parameters via consistent, history-guided masks. Experiments show that DictPFL reduces communication cost by 402-748$\times$ and accelerates training by 28-65$\times$ compared to fully encrypted FL, while outperforming state-of-the-art selective encryption methods by 51-155$\times$ in overhead and 4-19$\times$ in speed. Remarkably, DictPFL’s runtime is within 2$\times$ of plaintext FL, demonstrating, for the first time, that HE-based private federated learning is practical for real-world deployment. The code is publicly available at https://github.com/UCF-ML-Research/DictPFL. Yuzhang Shang, Shangqian Gao, Rui Ning, Mengxin Zheng, Xiaoqian Jiang, Qian Lou |
NeurIPS | 5 |
| 2025 | Deep Incomplete Multi-view Clustering via Multi-level Imputation and Contrastive Alignment
Yiming Du, Rui Ning, Lusi Li |
Neural Networks | 4 |
| 2024 | SEER: Backdoor Detection for Vision-Language Models through Searching Target Text and Image Trigger JointlyabstractThis paper proposes SEER, a novel backdoor detection algorithm for vision-language models, addressing the gap in the literature on multi-modal backdoor detection. While backdoor detection in single-modal models has been well studied, the investigation of such defenses in multi-modal models remains limited. Existing backdoor defense mechanisms cannot be directly applied to multi-modal settings due to their increased complexity and search space explosion. In this paper, we propose to detect backdoors in vision-language models by jointly searching image triggers and malicious target texts in feature space shared by vision and language modalities. Our extensive experiments demonstrate that SEER can achieve over 92% detection rate on backdoor detection in vision-language models in various settings without accessing training data or knowledge of downstream tasks. Liuwan Zhu, Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu |
AAAI | 2 |
| 2024 | MOSAIC: A Prune-and-Assemble Approach for Efficient Model Pruning in Privacy-Preserving Deep LearningabstractTo enable common users to capitalize on the power of deep learning, Machine Learning as a Service (MLaaS) has been proposed in the literature, which opens powerful deep learning models of service providers to the public. To protect the data privacy of end users, as well as the model privacy of the server, several state-of-the-art privacy-preserving MLaaS frameworks have also been proposed. Nevertheless, despite the exquisite design of these frameworks to enhance computation efficiency, the computational cost remains expensive for practical applications. To improve the computation efficiency of deep learning (DL) models, model pruning has been adopted as a strategic approach to remarkably compress DL models. However, for practical deep neural networks, a problem called pruning structure inflation significantly limits the pruning efficiency, as it can seriously hurt the model accuracy. In this paper, we propose MOSAIC, a highly flexible pruning framework, to address this critical challenge. By first pruning the network with the carefully selected basic pruning units, then assembling the pruned units into suitable HE Pruning Structures through smart channel transformations, MOSAIC achieves a high pruning ratio while avoiding accuracy reduction, eliminating the problem plagued by the pruning structure inflation. We apply MOSAIC to popular DL models such as VGG and ResNet series on classic datasets such as CIFAR-10 and Tiny ImageNet. Experimental results demonstrate that MOSAIC effectively and flexibly conducts pruning on those models, significantly reducing the Perm, Mult, and Add operations to achieve the global cost reduction without any loss in accuracy. For instance, in VGG-16 on Tiny ImageNet, the total cost is reduced to 21.14% and 29.49% under the MLaaS frameworks GAZELLE and CrypTFlow2, respectively. Qiao Zhang 0002, Rui Ning, Chunsheng Xin, Hongyi Wu |
AsiaCCS | 3 |
| 2024 | SPOT: Structure Patching and Overlap Tweaking for Effective Pipelining in Privacy-Preserving MLaaS with Tiny ClientsabstractMachine Learning as a Service (MLaaS) has paved the way for numerous applications for resource-limited clients, such as IoT/mobile users. However, it raises a great challenge for privacy, including both the data privacy of clients and model privacy of the server. While there have been extensive studies on privacy-preserving MLaaS, a direct adoption of current frameworks leads to intractable efficiency bottleneck for MLaaS with resource constrained clients. In this paper, we focus on MLaaS with resource constrained clients and propose a novel privacy-preserving framework called SPOT to address a unique challenge, the memory constraint of such clients, such as IoT /mobile devices, which results in significant computation stalls at the server in privacy-preserving MLaaS. We develop 1) a novel structure patching scheme to enable independent computations for sequential inputs at the server to eliminate the computation stall, and 2) a patch overlap tweaking scheme to minimize overlapped data between adjacent patches and thus enable more efficient computation with flexible cryptographic parameters. SPOT demonstrates significant improvement on computation efficiency for MLaaS with IoT /mobile clients. Compared with the state-of-the-art framework for privacy-preserving MLaaS, SPOT achieves up to 2 × memory utilization boost and a speedup up to 3 × on computation time for modern neural networks such as ResNet and VGG. Xiangrui Xu 0004, Qiao Zhang 0002, Rui Ning, Chunsheng Xin, Hongyi Wu |
ICDCS | 3 |
| 2023 | BlockFed: A High-Performance and Trustworthy Blockchain-Based Federated Learning FrameworkabstractRecent advances in Blockchain-based Federated Learning (FL) aim to address the inherent limitations of traditional FL, such as single node failure and the lack of an appropriate incentive mechanism. This approach replaces the central parameter server in FL with a blockchain that stores and disseminates updated models. However, its decentralized nature introduces significant communication and storage over-head, which considerably constrains its practical application. Additionally, as it allows participants to contribute to the shared model by training locally using private data, it is especially prone to privacy leaks and poisoning attacks. This study introduces a novel framework, BlockFed, designed to substantially reduce overhead and mitigate vulnerabilities in blockchain-based FL systems. Rui Ning, Chonggang Wang, Xu Li 0027, Robert Gazda, Hongyi Wu |
GLOBECOM | 1 |
| 2023 | ScanFed: Scalable Behavior-Based Backdoor Detection in Federated LearningabstractFederated Learning (FL) has been adopted in practical network applications and plays a critical role. As FL allows participants to contribute to the global model by training locally with private data, it is known particularly vulnerable to neural backdoor attacks. This paper proposes a new defense, ScanFed, against neural backdoor attacks to FL systems. It leverages the synchronous nature of FL to effectively single out malicious neuron candidates and further validate if they indeed hijack the model's behaviors. Compared to existing neural backdoor defenses, ScanFed has the following distinct properties. First, it is extremely computation-friendly that is six orders of magnitude faster than state-of-the-art behavior-based backdoor defenses, rendering it highly suitable for large-scale FL systems. Second, it inherits the precise nature of behavior-based backdoor detection, making it significantly more effective than similarity-based defenses against advanced attacks. Third, it is robust to biased models uploaded by clients with non-IID (Independent and Identically Distributed) data, which is very common in practical FL systems. In addition, it is a plug-n-play scheme that can be seamlessly integrated into existing FL systems. To the best of our knowledge, this is the first behavior-based defense that enables scalable, efficient and accurate neural backdoor detection of FL systems in non-IID scenarios. This work delivers a ScanFed prototype and fully tests it in various settings of datasets, neural architectures, and backdoor attacks. The experiments demonstrate ScanFed achieves competitive accuracy and minimal detection time. Rui Ning, Jiang Li 0001, Chunsheng Xin, Chonggang Wang, Xu Li 0027, Robert Gazda, Jin-Hee Cho, Hongyi Wu |
ICDCS | 1 |
| 2022 | Hibernated Backdoor: A Mutual Information Empowered Backdoor Attack to Deep Neural NetworksabstractWe report a new neural backdoor attack, named Hibernated Backdoor, which is stealthy, aggressive and devastating. The backdoor is planted in a hibernated mode to avoid being detected. Once deployed and fine-tuned on end-devices, the hibernated backdoor turns into the active state that can be exploited by the attacker. To the best of our knowledge, this is the first hibernated neural backdoor attack. It is achieved by maximizing the mutual information (MI) between the gradients of regular and malicious data on the model. We introduce a practical algorithm to achieve MI maximization to effectively plant the hibernated backdoor. To evade adaptive defenses, we further develop a targeted hibernated backdoor, which can only be activated by specific data samples and thus achieves a higher degree of stealthiness. We show the hibernated backdoor is robust and cannot be removed by existing backdoor removal schemes. It has been fully tested on four datasets with two neural network architectures, compared to five existing backdoor attacks, and evaluated using seven backdoor detection schemes. The experiments demonstrate the effectiveness of the hibernated backdoor attack under various settings. Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu, Chonggang Wang |
AAAI | 1 |
| 2022 | Hunter: HE-Friendly Structured Pruning for Efficient Privacy-Preserving Deep LearningabstractIn order to protect user privacy in Machine Learning as a Service (MLaaS), a series of ingeniously designed privacy-preserving frameworks have been proposed. The state-of-the-art approaches adopt Homomorphic Encryption (HE) for linear function and Garbled Circuits (GC)/Oblivious Transfer (OT) for nonlinear operation to improve computation efficiency. Despite the encouraging progress, the computation cost is still too high for practical applications. This work represents the first step to effectively prune privacy-preserving deep learning models to reduce computation complexity. Although model pruning has been discussed extensively in the machine learning community, directly applying the plaintext model pruning schemes offers little help to reduce the computation in privacy-preserving models. In this paper we propose Hunter, a structured pruning method that identifies three novel HE-friendly structures, i.e., internal structure, external structure, and weight diagonal to guide the pruning process. Hunter outputs a pruned model that, without any loss in model accuracy, achieves a significant reduction in HE operations (and thus the overall computation cost) in the privacy-preserving MLaaS. We apply Hunter in various deep learning models, e.g., AlexNet, VGG and ResNet over classic datasets including MNIST, CIFAR-10 and ImageNet. The experimental results demonstrate that, without accuracy loss, Hunter efficiently prunes the original networks to reduce the HE Perm, Mult, and Add operations. For example, in the state-of-the-art VGG-16 on ImageNet with 10 chosen classes, the total number of Perm is reduced to as low as 2% of the original network, and at the same time, Mult and Add are reduced to only 14%, enabling a significantly more computation-efficient privacy-preserving MLaaS. Qiao Zhang 0002, Rui Ning, Chunsheng Xin, Hongyi Wu |
AsiaCCS | 3 |
| 2022 | Most and Least Retrievable Images in Visual-Language Query Systems
Liuwan Zhu, Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu |
ECCV (37) | 2 |
| 2022 | TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic ClassifiersabstractWhile deep learning (DL)-based network traffic classification has demonstrated its success in a range of practical applications, such as network management and security control to just name a few, it is vulnerable to adversarial attacks. This paper reports TrojanFlow, a new and practical neural backdoor attack to DL-based network traffic classifiers. In contrast to traditional neural backdoor attacks where a designated and sample-agnostic trigger is used to plant backdoor, TrojanFlow poisons a model using dynamic and sample-specific triggers that are optimized to efficiently hijack the model. It features a unique design to jointly optimize the trigger generator with the target classifier during training. The trigger generator can thus craft optimized triggers based on the input sample to efficiently manipulate the model’s prediction. A well-engineered prototype is developed using Pytorch to demonstrate TrojanFlow attacking multiple practical DL-based network traffic classifiers. Thorough analysis is conducted to gain insights into the effectiveness of TrojanFlow, revealing the fundamentals of why it is effective and what it does to efficiently hijack the model. Extensive experiments are carried out on the well-known ISCXVPN2016 dataset with three widely adopted DL network traffic classifier architectures. TrojanFlow is compared with two other backdoor attacks under five state-of-the-art backdoor defenses. The results show that the TrojanFlow attack is stealthy, efficient, and highly robust against existing neural backdoor mitigation schemes. Rui Ning, Chunsheng Xin, Hongyi Wu |
INFOCOM | 1 |
| 2021 | CLEAR: Clean-up Sample-Targeted Backdoor in Neural NetworksabstractThe data poisoning attack has raised serious security concerns on the safety of deep neural networks, since it can lead to neural backdoor that misclassifies certain inputs crafted by an attacker. In particular, the sample-targeted backdoor attack is a new challenge. It targets at one or a few specific samples, called target samples, to misclassify them to a target class. Without a trigger planted in the backdoor model, the existing backdoor detection schemes fail to detect the sample-targeted backdoor as they depend on reverse-engineering the trigger or strong features of the trigger. In this paper, we propose a novel scheme to detect and mitigate sample-targeted backdoor attacks. We discover and demonstrate a unique property of the sample-targeted backdoor, which forces a boundary change such that small "pockets" are formed around the target sample. Based on this observation, we propose a novel defense mechanism to pinpoint a malicious pocket by "wrapping" them into a tight convex hull in the feature space. We design an effective algorithm to search for such a convex hull and remove the backdoor by fine-tuning the model using the identified malicious samples with the corrected label according to the convex hull. The experiments show that the proposed approach is highly efficient for detecting and mitigating a wide range of sample-targeted backdoor attacks. Liuwan Zhu, Rui Ning, Chunsheng Xin, Chonggang Wang, Hongyi Wu |
ICCV | 2 |
| 2021 | Invisible Poison: A Blackbox Clean Label Backdoor Attack to Deep Neural NetworksabstractThis paper reports a new clean-label data poisoning backdoor attack, named Invisible Poison, which stealthily and aggressively plants a backdoor in neural networks. It converts a regular trigger to a noised trigger that can be easily concealed inside images for training NN, with the objective to plant a backdoor that can be later activated by the trigger. Compared with existing data poisoning backdoor attacks, this newfound attack has the following distinct properties. First, it is a blackbox attack, requiring zero-knowledge of the target model. Second, this attack utilizes "invisible poison" to achieve stealthiness where the trigger is disguised as `noise', and thus can easily evade human inspection. On the other hand, this noised trigger remains effective in the feature space to poison training data. Third, the attack is practical and aggressive. A backdoor can be effectively planted with a small amount of poisoned data and is robust to most data augmentation methods during training. The attack is fully tested on multiple benchmark datasets including MNIST, Cifar10, and ImageNet10, as well as application specific data sets such as Yahoo Adblocker and GTSRB. Two countermeasures, namely Supervised and Unsupervised Poison Sample Detection, are introduced to defend the attack. Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu |
INFOCOM | 1 |
| 2020 | GangSweep: Sweep out Neural Backdoors by GANabstractThis work proposes GangSweep, a new backdoor detection framework that leverages the super reconstructive power of Generative Adversarial Networks (GAN) to detect and ''sweep out'' neural backdoors. It is motivated by a series of intriguing empirical investigations, revealing that the perturbation masks generated by GAN are persistent and exhibit interesting statistical properties with low shifting variance and large shifting distance in feature space. Compared with the previous solutions, the proposed approach eliminates the reliance on the access to training data, and shows a high degree of robustness and efficiency for detecting and mitigating a wide range of backdoored models with various settings. Moreover, this is the first work that successfully leverages generative networks to defend against advanced neural backdoors with multiple triggers and their polymorphic forms. Liuwan Zhu, Rui Ning, Cong Wang 0006, Chunsheng Xin, Hongyi Wu |
ACM Multimedia | 2 |
| 2020 | DeepMag+: Sniffing mobile apps in magnetic field through deep learning
Rui Ning, Cong Wang 0006, Chunsheng Xin, Jiang Li 0001, Hongyi Wu |
Pervasive Mob. Comput. | 1 |
| 2019 | CapJack: Capture In-Browser Crypto-jacking by Deep Capsule Network through Behavioral AnalysisabstractThis work proposes an innovative approach, named CapJack, to detect in-browser malicious cryptocurrency mining activities by using the latest CapsNet technology. To the best of our knowledge, this is the first work to introduce CapsNet to the field of malware detection through system behavioral analysis. It is particularly effective to detect malicious miners under multitasking environments where multiple applications run simultaneously. Experimental data show appealing performance of CapJack, with a detection rate of as high as 87% instantly and 99% within a window of 11 seconds. Rui Ning, Cong Wang 0006, Chunsheng Xin, Jiang Li 0001, Liuwan Zhu, Hongyi Wu |
INFOCOM | 1 |
| 2018 | Puncturable Attribute-Based Encryption for Secure Data Delivery in Internet of ThingsabstractWhile the Internet of Things (IoT) is embraced as important tools for efficiency and productivity, it is becoming an increasingly attractive target for cybercriminals. This work represents the first endeavor to develop practical Puncturable Attribute Based Encryption schemes that are light-weight and applicable in IoTs. In the proposed scheme, the attribute-based encryption is adopted for fine grained access control. The secret keys are puncturable to revoke the decryption capability for selected messages, recipients, or time periods, thus protecting selected important messages even if the current key is compromised. In contrast to conventional forward encryption, a distinguishing merit of the proposed approach is that the recipients can update their keys by themselves without key re-issuing from the key distributor. It does not require frequent communications between IoT devices and the key distribution center, neither does it need deleting components to expunge existing keys to produce a new key. Moreover, we devise a novel approach which efficiently integrates attribute-based key and punctured keys such that the key size is roughly the same as that of the original attribute-based encryption. We prove the correctness of the proposed scheme and its security under the Decisional Bilinear Diffie-Hellman (DBDH) assumption. We also implement the proposed scheme on Raspberry Pi and observe that the computation efficiency of the proposed approach is comparable to the original attribute-based encryption. Both encryption and decryption can be completed within tens of milliseconds. Tran Viet Xuan Phuong, Rui Ning, Chunsheng Xin, Hongyi Wu |
INFOCOM | 2 |
| 2018 | DeepMag: Sniffing Mobile Apps in Magnetic Field through Deep Convolutional Neural NetworksabstractIn this paper, we report a newfound vulnerability on smartphones due to the malicious use of unsupervised sensor data. We demonstrate that an attacker can train deep Convolutional Neural Networks (CNN) by using magnetometer or orientation data to effectively infer the Apps and their usage information on a smartphone with an accuracy of over 80%. Furthermore, we show that such attacks can become even worse if sophisticated attackers exploit motion sensors to cluster the magnetometer or orientation data, improving the accuracy to as high as 98%. To mitigate such attacks, we propose a noise injection scheme that can effectively reduce the App sniffing accuracy to only 15% and at the same time has negligible effect on benign Apps. Rui Ning, Cong Wang 0006, Chunsheng Xin, Jiang Li 0001, Hongyi Wu |
PerCom | 1 |